Skip to main content
USTelecom — The Broadband Association
Sample profile — content is illustrative. Verify every name, date, and status against official sources before use.
Back to Agency Atlas
CISAHigh activityReview recommended · 2026-07-10

Cybersecurity and Infrastructure Security Agency

Cross-sector incident-reporting regulator (CIRCIA), home of the ICT Supply Chain Risk Management Task Force, source of secure-by-design guidance, and the Communications Sector’s SRMA (Sector Risk Management Agency) partner. Also a member of the Federal Acquisition Security Council (FASC).

One-minute briefing

Agency snapshot

CIRCIA is the single most consequential pending item for members. The statutory October 2025 deadline was missed; the target moved to May 2026, then slipped again after the DHS appropriations lapse (February 14 to April 30, 2026) forced postponement of the sector town halls (re-run June 15–18, 2026). The Unified Agenda now shows a September 2026 target for the final rule — but that is an agency projection, and the compliance clock likely will not start until late 2026 at the earliest, with further slippage plausible. Core obligations are expected to hold: 72-hour covered-incident reports, 24-hour ransom-payment reports, roughly 316,000 covered entities across all 16 sectors. The Unified Agenda also projects September 2026 for two companion FAR cyber rules.

4
Active initiatives
3
Upcoming deadlines
3
Priority topics
Most important thing right now

Stand up 72-hour incident / 24-hour ransom-payment reporting workflows now in anticipation of the CIRCIA final rule, and treat the September 2026 date as a target rather than a hard deadline.

Mandate & jurisdiction

What this agency does

CIRCIA will impose mandatory incident-reporting timelines on communications providers, and the companion FAR cyber rules will flow the same expectations into federal contracts.

CIRCIA rulemaking

Will require covered entities to report covered cyber incidents within 72 hours and ransom payments within 24 hours.

Sector coordination

Serves as SRMA for the Communications Sector on threats and resilience.

Supply-chain task force

Hosts the ICT SCRM Task Force and issues secure-by-design guidance.

Information sharing

Administers threat-indicator sharing with liability protections under CISA 2015.

Jurisdiction

  • Cross-sector cyber-incident reporting (CIRCIA)
  • ICT Supply Chain Risk Management Task Force
  • Communications Sector risk management (SRMA)
  • Information-sharing program (CISA 2015)
Who should care

Security operations, legal, and incident-response teams.

Operational

Incident detection, classification, and reporting readiness.

Compliance

Mandatory reporting timelines and recordkeeping under CIRCIA and the FAR cyber rules.

Procurement

Vendor incident-notification terms aligned to CIRCIA and standardized FAR cyber requirements.

Initiatives & deadlines

What they are working on now

UpcomingPendingCIRCIA incident reporting 2026-09-30

CIRCIA cyber-incident reporting final rule

The single most consequential pending item for members. The statutory October 2025 deadline was missed; the target moved to May 2026, then slipped again after the DHS appropriations lapse (February 14 to April 30, 2026) postponed the sector town halls originally set for March 9 to April 2. Town halls were re-run June 15–18, 2026. The Unified Agenda now shows a September 2026 target. Core obligations are expected to hold: 72-hour covered-incident reports, 24-hour ransom-payment reports, and roughly 316,000 covered entities across all 16 sectors. Note: the September 2026 date is an agency projection (target), not a statutory deadline, and further slippage is plausible.

UpcomingPendingFAR cyber rules 2026-09-30

FAR standardized contractor cybersecurity requirements rule (CISA/FAR joint)

The Unified Agenda projects September 2026 finalization for a rule standardizing contractor cybersecurity requirements across federal acquisitions. It belongs in the Atlas as a CISA/FAR joint item.

UpcomingPendingFAR cyber rules 2026-09-30

FAR cyber threat & incident reporting / information-sharing rule (CISA/FAR joint)

The Unified Agenda also projects September 2026 finalization for a rule on contractor cyber threat and incident reporting and information sharing. Tracked as a CISA/FAR joint item alongside CIRCIA.

UpcomingRecently changedCyber incident and software assurance 2026-12-11

CISA 2015 information-sharing reauthorization

The Cybersecurity Information Sharing Act of 2015 did not sunset on September 30. The Continuing Appropriations and Extensions Act, 2027 (H.R. 6500), signed September 2, 2026 after the Senate passed it 90-6 and the House 370-48, funds the government through December 11, 2026 and moves the CISA 2015 sunset to the same date. It is the fourth short-term patch since the original September 30, 2025 sunset (October 2025 CR to January 30, 2026; February 2026 omnibus to September 30; now December 11), with no substantive changes to definitions, liability, FOIA or antitrust protections. The NDAA was never the vehicle: Senate cloture on the motion to proceed to S. 4784 failed July 14 (50-46) and no further procedural step is recorded; H.R. 8800 passed the House July 22 (219-206). The next cliff now lands on the funding deadline, and a December omnibus or a fifth CR is the probable carrier.

Upcoming dates

  • 2026-09-30CIRCIA final rule — September 2026 target (agency projection, not statutory)
  • 2026-09-30FAR cyber companion rules — September 2026 target
  • 2026-12-11CISA 2015 information-sharing authority sunset (extended by CR to December 11)
Key decision-makers

Leadership to know

We focus on the roles whose decisions reach members, and why each one matters — not biographical trivia. Names are intentionally withheld until verified against an official source.

Nick Andersen
Acting Director

Why it mattersLeads national cyber defense and owns the CIRCIA rulemaking; serving in an acting capacity — no Senate-confirmed Director in place.

Review recommended
Working Group analysis

What we are watching

Confidence: DevelopingActive situation; details are still shifting.

What changed

  • CIRCIA final rule slipped from October 2025 (statutory) to a May 2026 then September 2026 target after the DHS appropriations lapse.
  • Sector town halls re-run June 15–18, 2026.
  • Two companion FAR cyber rules also projected for September 2026.

What we are watching

  • Final CIRCIA covered-entity/incident definitions across ~316,000 entities.
  • Whether the September 2026 targets hold or slip again.
  • Long-term CISA 2015 reauthorization.

Member exposure

  • New mandatory reporting duties for covered providers (72h incidents / 24h ransom payments).
  • Contract-level cyber and reporting clauses via the FAR companion rules.
  • Liability-protection continuity for threat-sharing.

Recommended preparation

  • Build 72h/24h reporting workflows now.
  • Map CIRCIA against CMMC and the FAR cyber rules to avoid duplicative reporting.
  • Track the September 30, 2026 CISA 2015 sunset in legal planning.

Open questions

  • Exactly which communications entities will be "covered," and when does the compliance clock actually start?
Primary references

Sources & verification

Agency-level sources

This profile is a sample interface. Leadership names, dates, regulatory status, and figures must be confirmed against current official sources before any member distribution.